Privacy Policy
This explains how Holder handles personal data. It covers two different things: the data about you and your account, where Holder is the controller; and the data about your clients that you store in Holder, where you are the controller and Holder is your processor.
Last updated 16 September 2026
Who we are
Holder is provided by Holder Software Ltd, a company registered in England and Wales (company number 17329477), registered office 128 City Road, London EC1V 2NX. For the data we control, Holder Software Ltd is the data controller. We are registered with the Information Commissioner’s Office (registration number ZC167019). You can reach us about privacy at info@holder.cloud.
Who controls what
Holder is the controller for your account and contact data — the information needed to provide you the service and bill you for it — together with the usage, diagnostic and security data we generate to run and protect the service.
You are the controller for your clients’ personal data — the records, notes, bookings and messages you keep in Holder. Holder processes that data only on your instructions, under our Data Processing Agreement.
What we collect about you
- •Account and contact details — your name, practice name, email and sign-in credentials;
- •Billing information — handled by our payment processor, Stripe; we receive limited details to manage your subscription, but we do not store full card numbers;
- •Usage and diagnostic data — limited technical information, such as log and device data, needed to run, secure and improve the service.
Why we use it, and our lawful basis
We use your data to provide the service (performance of our contract with you), to keep it secure and to improve it (our legitimate interests in running a safe, reliable product), and to meet our legal obligations, such as tax and accounting. Where we rely on legitimate interests, we have weighed them against your rights. If we ever send you optional marketing, we do so on the basis of your consent or an applicable soft opt-in, and you can withdraw at any time.
Your clients’ data
The client data you store is controlled by you. We do not sell it, and we never use it to train AI models. No one at Holder accesses it without your written permission, except where strictly necessary to provide support you have asked for, or to comply with the law. It is processed only to provide the features you use, under our Data Processing Agreement.
AI features
Where you switch on AI features, the relevant data is sent to our AI provider, Anthropic, solely to produce the output you asked for. Under Anthropic’s commercial terms, your inputs and outputs are never used to train AI models, and are automatically deleted within 30 days, other than narrow exceptions such as a legal hold. Anthropic contracts with us through its EU entity in Ireland under a Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for any transfers outside the UK and EEA. Holder does not make significant decisions about you or your clients by solely automated means (within the meaning of Articles 22A to 22D UK GDPR). AI features can be switched off entirely, and the Essentials plan includes none — with one exception that applies on every plan: default wording in languages other than English is produced by AI translation of Holder’s standard text, and translation sharing is screened by AI, as described under Translations. That processing involves Holder’s standard wording and your edits of it, never your clients’ data.
Translations
Default wording in languages other than English is produced by AI translation of Holder’s standard text, which practitioners can review and edit. Where you translate or correct that standard text yourself, we may use your version as the default wording for that language for other practitioners. Before that happens, it is screened by automated checks — including AI review through our AI provider — to exclude anything identifying, and nothing is linked to your account. We rely on our legitimate interests in improving the service for this, and you can turn translation sharing off in Settings. Wording you write yourself is never shared.
Contact research
Holder offers an optional feature that lets a practitioner generate a short research brief about one of their professional contacts. When a practitioner uses it, Holder — through Anthropic’s AI and its web search tool — looks up publicly available information about the named contact, such as professional profiles, company websites, public social bios, and news or media mentions, and writes a summary into the practitioner’s account. This concerns a practitioner’s professional contacts — third parties — rather than our account holders.
The information comes from publicly available and third-party sources, found using a third-party search service engaged by our AI provider; that service operates under its own terms, and a contact’s name may be sent to it as a search query. The practitioner, and Holder where it acts as a controller, rely on legitimate interests (UK GDPR Article 6(1)(f)) to support relevant, informed professional outreach to known contacts. We do not target special-category data, and we instruct our systems not to infer or record it.
A brief is an AI-generated summary. It is personal data in its own right, it may contain inaccuracies, and it is reviewed by a person before it is used; it is never used to make a solely automated decision with legal or similarly significant effect. Search queries and contact identifiers processed by Anthropic and the search service may involve transfers outside the UK, covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum; the data is not used to train models and is deleted within 30 days. A brief is kept only while the contact is active in the practitioner’s account, and no longer than 12 months, after which it is deleted or refreshed; if the contact is deleted, the brief is deleted with it.
If you have been researched, you can object to this processing (Article 21), ask for a copy of the brief, have inaccurate information corrected, and have it erased. Contact us at info@holder.cloud, or the practitioner who holds your details.
Sub-processors
We use a small number of carefully chosen sub-processors to run the service — for hosting and database, application hosting, making and storing encrypted off-site backups, payments, email and SMS delivery, AI, maps and travel-time calculations, and, for online sessions, video. They are named in our Data Processing Agreement, which we keep up to date. We give advance notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds.
Champions (referrals)
Some practitioners recommend Holder through our invitation-only champions programme and are paid a commission when a practice they refer subscribes. If you join through a champion’s link or code, we record that attribution and show the champion your practice name, your signup date, whether your account is active, and the commission amounts arising — nothing else, ever: not your clients, your finances, or anything inside your account. Attribution comes from the link or code you use at signup; we set no tracking cookies for it. Our lawful basis is our legitimate interest in running the programme. Questions: info@holder.cloud.
Where your data is stored, and international transfers
Your account data and your clients’ data are stored on secure servers in the EU (Ireland). Some of our sub-processors may process limited data outside the UK and EEA. Where that happens, the transfer is covered by an approved safeguard — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, or an applicable adequacy decision. You can ask us for details of the safeguard that applies.
How long we keep it
We keep your account data for as long as your account is active. If your account is suspended — for example after a failed payment — and is not restored, we keep your data for up to 6 months from suspension so that you can come back to it, or export it, and we will email you at least 14 days before any such deletion. If you close your account yourself, we keep your data for six months from your closure request, in case you change your mind — you can cancel the closure and reactivate at any time within that window. If you would rather not wait, you can delete everything immediately instead, in Settings → Data. After that six-month window (or an immediate deletion request), we delete or anonymise your data, except where we need to keep certain records for longer to meet legal obligations — for example, billing and tax records, which we keep for 6 years. Your clients’ data is returned or deleted in line with our Data Processing Agreement. You can export or delete data at any time while your account is active.
The limited technical data we generate to keep the service secure — such as the short-lived counters, based on network address or on a scrambled code made from an email address, that we use to detect and block abusive sign-in, booking and form attempts — is kept only as long as needed for that purpose, no more than a few days. We may refuse a form sent from a known exit point of Tor, a network that hides where a visitor is connecting from; to check, we compare the visitor’s network address with the Tor Project’s public list of those exit points, which we download, and we send nothing about the visitor to the Tor Project.
One record is kept for longer, on behalf of the practice concerned. When a practice’s website form leads to an automatic first email — such as a welcome email after someone joins its mailing list, or an acknowledgement of an enquiry — we keep a scrambled code made from the email address it is addressed to (not the address itself), together with the practice and the time of that email. We use it only to make sure the same email address is sent no more than one such email from that practice in any 30 days — which limits how far anyone can use the practice’s forms to send emails to someone who never asked for them — and we delete it in our daily clean-up once 31 days have passed since the last one.
Your rights
You have the rights given to you under the UK GDPR and applicable data-protection law — including access, correction, deletion, restriction, portability and objection. To exercise them, contact us at info@holder.cloud, and we will respond within the time the law allows, usually one month. Where your request concerns data that a practitioner controls (their clients’ data), we will direct it to that practitioner, who is the controller for it.
If you are unhappy with how we handle your data, you can complain to us directly — email info@holder.cloud or use our data protection complaints form at holder.cloud/data-protection-complaint — and we will acknowledge your complaint within 30 days and keep you informed while we put things right. You can also complain to the Information Commissioner’s Office (ico.org.uk). We would, of course, rather you came to us first.
Security
We protect data with encryption in transit and at rest, strict per-practice isolation enforced at the database, access controls on the principle of least privilege, and regular review of our measures. Cookies are covered by our Cookie Policy.
Changes and governing law
We may update this policy and will note the date of the latest version above; where a change is material, we will tell you. This policy is governed by the law of England and Wales.